Quote verification

This proves the quote below is recorded by Citatio exactly as displayed and has not been altered since it was committed and anchored. It documents Citatio's crawl observation; it does not imply endorsement by the source platform. The quote links to the original review.

“After selecting Dropbox, the app provides a nice note that Dropbox authorization is not possible as the app is still in development and no further users can be added ?? Super professional.”

Checks (re-run on this request)

Proof data

Record hash (SHA-256)
0a1f91afd711015c44d40b67a244f167c6f00efe56c507a6b073b052b8d7ca36
Signature (Ed25519, base64)
3xa7cXxPGU9qA8QoqzsMufuYBG4prCW31LY02nVf7T8rzK+c+hAVY1laK4RD0t2Su3WrQmZbwkPgwG3KOmO3Dw==
Merkle root
97eb1062a862b99998bef0a84476eb3c3812bb77c2cb927f4fd2933b59da9e3d
Merkle path
["0a1beda623be49de85347b217bbd023c0b0c03b67e4f8e1fc686ca7c51e9a514","9ed375e376180ca43c7f3cae62b90f79011cb5de58746a27c99b1e28d9c5579f","56bb9bb32aa7a60ed6755d66c80dba6ff819e50e25c7673d080b5fc94e014e03","004ff813bdbde55511081c6b01016a193fa542c868cfceea4b02bf815c103126","3b4a2299ca917cff721dd690910c6e68dfde6ede313b2b37a1a1bd0ec57fa5ff","63d6bc67411fc1de36b54bb2d7e66daee029102f8c512812ddffddc43814f6a0","c57821ca05f238c52884e49f5468eefa3dd29bf4a9bb8118132b29cae602e153","147ba0c9f3aeda1d037068e591c9604a035b8a4a6337cded1f47e0ad7daa12e9","e9869695599de07dc9eb7f9889abb19b6fc44a8486f32f81a4f3a377c2c79216","929021c2cceb1bc18530741bdc9b0bc7642b8907f17a6184502e6a515819f766","c88b3d8b7a19b4ad39809cf40205783f933d9a74fff3512cfce9fe04f3d1b7d2","6c14202f6f4d89338c781140a2504c6d469b19d300474270ba84f87831aa8464","5b47260d99d2c4ad6e0d963995c990c8506dbf10eb0b146a116c3fc6ba348071","a9559f2ca8536f2c18bf059f3f0099d62235a93ac35dc17b09967d392b72be7f","01242865574478f13dcf9d888236d7a907264abdb87f360db7db06de0945075a"]
Anchored
2026-09-11
Public log entry
search.sigstore.dev, log index 2789279696 · entry 108e9186e8c5677a3885…
Expected log hash
05c7009ecf7ce5cf315c252c2a1dd135e64989a02cacdaaa3c5a87412a2e921c The log entry's spec.data.hash.value must equal this value: the SHA-256 of the Merkle root string above. Recompute it yourself from the root to confirm.
Canonical record
{"dataset_version":"v1789017464005","kind":"published-quote","locale":"en","page":"theme:pixum/service/en","quote":"After selecting Dropbox, the app provides a nice note that Dropbox authorization is not possible as the app is still in development and no further users can be added ?? Super professional.","rating":3,"review_date":"2025-12-12","source":"Apple App Store","source_url":"https://apps.apple.com/de/app/id1319898516?see-all=reviews","v":1}

Verify in the public log

  1. Open the Rekor entry (pre-filled with this proof's log index).
  2. In the entry, compare spec.data.hash.value with the "Expected log hash" above: it is the SHA-256 of the Merkle root string (97eb1062a862…), which ties this proof's root to the log entry.
  3. Decode spec.signature.publicKey.content from base64: it must equal Citatio's published key at /.well-known/citatio-signing.json.
  4. The entry's integratedTime is the independent timestamp: the root, and with it this quote, existed no later than that moment.
  5. Locally, without any Citatio infrastructure: SHA-256 the canonical record (must equal the record hash), verify the Ed25519 signature against the public key, and fold the hash through the Merkle path (sorted-pair SHA-256) to reach the anchored root.